Eitsify logo

We consult and organize the security of your data and protection of your IT systems.
Leave us your email and we will contact you as soon as possible.

Implementing information security in a matrix organization
Organizations that have many branches, subsidiaries, or multiple physical locations and practice matrix management face quite complex challenges when implementing information security.
If in a multi-level organization a large part of the implementation of information security measures, e.g. IT, Finance, Administration, is concentrated in one central function, the role of this unit in ensuring the information security of the entire organization increases. In such a situation, it is especially important that the methodology used is transparent, flexible and certainly scalable. This is where the value of one unified information security tool comes into play – Eitsify App supports the practical implementation of the E-ITS or ISO/IEC 27001 standard also in multi-level organizations.
One information security standard, multiple realities
Implementing an information security standard requires that an organization implements measures in a risk-based and justified manner. In practice, this means that:
  • some information security measures apply similarly to all subordinate institutions&nbps; (central access management, logging, backup policies, internal rules, fire safety regulations, etc.),
  • some information security measures are subsidiary or service-based  (local physical security solutions, specific information systems, subsidiary-based policies and procedures),
  • some measures are hybrid – the general principles are central, but the details of implementation depend on the specific sub-agency.
Without a good tool, this usually means fragmented documentation, many different files in different locations, and a lot of manual work. Over time, you lose track of what measures have been implemented, at what level, and why. Also, when updating a standard measure or control, the question may arise whether all measures are still properly implemented in all sub-units.
Complexity of (information) assets and structure
In organizations with distributed management, the asset structure is never too simple:
  • one subsidiary may have several physical locations (e.g. three different buildings in different cities),
  • at the same time, one building may be used by several sub-departments or even different organizations,
  • information systems and services can be managed by central IT or under local responsibility.
When implementing information security, it is important that assets, risks and measures are logically linked to each other. Eitsify App allows you to describe assets exactly as they exist in reality: regardless of whether the relationship is through a location, a subsidiary or a service. This provides a realistic basis for risk assessment and the selection of measures.
Multifunctional employees in a matrix management organization
In multi-layered organizations, employee roles are also multi-level, not subject to simple boundaries:
  • some employees are house- or location-based
  • some employees move between multiple buildings and institutions
  • some employees perform roles across multiple organizations or subsidiaries or are outsourced as a service
In such a situation, it is not reasonable to describe information security only in terms of organization. A role-based approach is needed, where access, responsibilities and measures are related to roles, not just to structural units. A single tool helps ensure that the same principles apply to people in the same role: regardless of the location or function they currently perform.
Implementing an information security standard as a management framework in a distributed organization
Implementing an information security standard is not just about meeting requirements, but rather a management framework. When information security implementation is supported by a good tool, the IT department can focus on the content: mitigating risks, justifying decisions, and supporting the organization, not on maintaining spreadsheets. A distributed and multi-layered organizational structure does not have to be a weakness for information security. With the right approach and the right tool, it can become a strength: standardized, yet flexible information security that grows with the organization.
Contact
Contact us
We’ll help you find the best information security solutions!
  • Eitsify Ltd: Consulting | Auditors | CISOaaS | InfoSec Tool
  • (+372) 58 160 100
  • info@eitsify.com